Sr. GRC Analyst

Remote

About evermore

evermore is a technology company that administers Smart Benefits to connect people to products and services they need, when they need them, so they can live healthier lives. We partner with payers and retailers to deliver expansive benefits for things like healthy foods, OTC medications, or transportation. evermore is reinventing benefits administration so that everyone benefits with more value for each and better outcomes for all. evermore is a Series B stage company, backed by leading investors including General Catalyst, Define Ventures, Lightspeed Venture Partners, Pinegrove Capital Partners, and Qiming Venture Partners.  

The Job at a Glance 

Working within the security function, the GRC Analyst will be responsible for managing the company’s regulatory and self-driven compliance targets, primarily utilizing the Vanta platform. This role requires expertise across a broad scope of frameworks, including PCI, HITRUST, HITECH, HIPAA (Security Rule), SOC 2 Type 2, and FEDRAMP Moderate (NIST 800-53). A core function is to handle evidence gathering for all audits, present assessment results, and conduct necessary gap/fit analyses, especially for advanced controls like those required for FedRAMP Moderate. The analyst will also coordinate and support high-volume commercial and state audits. 

What You Will Do 

Working within an organization created at the intersection of health care, retail and financial technology, no two days will look the sameTypical responsibilities of the role include:  

  • Manage regulatory and self-driven infosec compliance targets, including conducting work within the Vanta platform. 
  • Gather necessary evidence for all security audits and present subsequent assessment results. 
  • Review and determine the correct security training for all employees  
  • Serve as the primary resource for internal gap/fit analysis on new controls, such as those required to meet the definition of FedRAMP Moderate. 
  • Coordinate commercial audits/assessments and collaborate closely with the legal and compliance function on privacy compliance matters.   
  • Support compliance across established frameworks including PCI, HITRUST, HITECH, HIPAA, NIST and SOC 2 Type 2. 
  • Perform and manage security risk reviews for third-party vendors. 
  • Lead and support Disaster Recovery (DR) and Business Continuity Planning (BCP) activities, including planning, testing, and documentation to ensure organizational resilience. 
  • Participate in risk management activities, including maintaining and updating risk registers, advising stakeholders on mitigation strategies, and monitoring risk metrics across the organization. 

About You 

While every candidate brings a unique resume and prospective, an ideal candidate will include:  

  • Proven experience managing or executing compliance programs covering frameworks such as PCI, HITRUST, HIPAA, and SOC 2 Type 2. 
  • Demonstrated ability to perform internal gap/fit analysis related to complex security control standards 
  • Experience with audit tooling environments like Vanta, including the collection and management of audit evidence. 
  • Background in coordinating external commercial and state-level compliance assessments. 
  • Familiarity with HITECH requirements, HIPAA Security Rule and FedRAMP. 
  • Strong organizational skills necessary to manage high-volume, 'bursty' audit assessment workloads. 
  • Ability to work proactively and understand what is needed to accomplish compliance objectives. 
  • Bachelor’s degree or similar experience strongly preferred. 


Other Requirements

  • Travel may be required from time to time as part of the role, for company events and business needs
  • evermore is a remote-first, distributed workforce. Candidates should be comfortable with, and equipped to work within, a distributed remote team, including having reliable internet access and basic home office equipment. evermore will provide a work laptop, and mouse/keyboard upon request   
  • Legal authorization to work in the US is required. At this time, evermore will not consider candidates who need sponsorship, now or in the future 
  • All offers for employment are contingent upon successful completion of a background check 

What We Offer 

  • Competitive base salary ranging from $166,050 to $219,625 discretionary bonus, and equity; depending on experience/qualifications
  • Benefits  
    • Medical, Dental, and Vision insurance with 90% paid employer premium contributions for all tiers 
    • 100% Employer Paid Short-Term & Long-Term Disability 
    • 100% Employer Paid Basic Life Insurance Policy  
    • Employee Assistance Program (EAP) 
    • 401(k) Program
  • Discretionary PTO
  • Paid holidays
  • Parental Leave
  • Flexible work schedule within core hours
  • Work anywhere in the USA as we are a fully distributed team from coast to coast 

Soda Health Inc. dba evermore is an equal opportunity employer, Minority/Female/Disability/Veteran/LGBTQIA+ – proudly embracing diversity in all its manifestations. Applicants requiring reasonable accommodation for the application and/or interview process should notify a representative of the People Operations Team via Careers@sodahealth.com. 

evermore participates in E-Verify, the federal program for electronic verification of employment eligibility. 

To all recruitment agencies: evermore does not accept agency resumes, please do not forward them to any Soda Health employees. 

 

Create a Job Alert

Interested in building your career at evermore? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...

Requirement of Background Check. All offers for employment are contingent upon successful completion of a background check.

Select...

Employment Authorization & Sponsorship. Legal authorization to work in the US is required. At this time, evermore will not consider candidates who need sponsorship, now or in the future. 

Select...
Select...

EEO ~ Invitation to Self-Identify

evermore is committed to providing Equal Employment Opportunities. We would appreciate it if you could answer the following questions, although it is not required. Please note that this information will not be used to make employment decisions and will only be utilized in compliance with federal and state regulations. We request this information to assess the effectiveness of our outreach and adjust our recruitment efforts to ensure that we reach all communities in the US.  

At evermore, we strictly comply with our Equal Employment Opportunity policy and do not discriminate based on any protected group status as outlined in applicable law. 

Veteran Status 

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. Classification of protected categories is as follows: 

 A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability. 

 A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service. 

 An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense. 

 An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985. 

 

Disability 

How do you know if you have a disability? 

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to: 

  • Alcohol or other substance use disorder (not currently using drugs illegally) 
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS 
  • Blind or low vision 
  • Cancer (past or present) 
  • Cardiovascular or heart disease 
  • Celiac disease 
  • Cerebral palsy 
  • Deaf or serious difficulty hearing 
  • Diabetes 
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders 
  • Epilepsy or other seizure disorder 
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome 
  • Intellectual or developmental disability 
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD 
  • Missing limbs or partially missing limbs 
  • Long-term mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports 
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS) 
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities 
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury 
Select...
Select...
Select...
Select...